**CISA Issues New Cyber Guidance for Federal Agencies and Critical Infrastructure**
The Cybersecurity and Infrastructure Security Agency (CISA) has released a series of new cyber guidelines aimed at federal agencies, contractors, and critical infrastructure organizations. This push comes in response to rising concerns over cyber attacks on municipal water systems and ongoing debates surrounding open-source artificial intelligence (AI) systems. Over the past week, CISA issued five advisories and updated tools designed to help agencies securely adopt cloud services.
One of the key advisories urged the water and wastewater sector to strengthen protections for operational technology (OT) systems, particularly programmable logic controllers (PLCs). Threat actors have been known to target exposed PLCs, modifying passwords to lock operators out and altering IP addresses to disconnect systems, leading to boil water notices and manual operations. While such threats have been warned about previously, these advisories highlight ongoing vulnerabilities, especially as investigations explore potential state-backed cyber activities targeting water facilities across multiple states.
In addition, CISA released “Advice for Isolating Vital Systems,” a collaborative effort with the Australian Signals Directorate and other international partners. This guidance focuses on helping critical infrastructure owners and operators safeguard essential OT systems from potential threats, ensuring resilience during crises through manual or alternative Supervisory Control and Data Acquisition (SCADA) pathways.
CISA also ventured into the contentious realm of open-source AI. Its new guide, “Open Source Software: Security Principles and Practices,” provides federal agencies with a framework to review and approve open-source software while managing associated risks. The guidance emphasizes transparency, particularly for open-source AI systems, urging agencies to fully understand components like training data before designating software as open source.
Two other significant updates include the refreshed minimum elements for Software Bill of Materials (SBOMs) and improvements to the Secure Cloud Business Applications (SCuBA) program. The SBOM update, first issued in 2021, now covers all software types, including open-source and AI software, aiming to enhance risk-informed decision-making and supply chain management. Meanwhile, SCuBA’s updated configuration baselines for Google Workspace products aim to prevent cloud misconfigurations, supporting compliance with federal security requirements.
—
### FAQ
**What is CISA and why is it issuing these new guidelines?**
CISA, the Cybersecurity and Infrastructure Security Agency, is a U.S. government agency responsible for protecting national assets from cyber threats. The new guidelines respond to recent cyber attacks on water systems and the evolving debate around open-source AI, aiming to bolster cybersecurity across critical infrastructure.
**What are the threats facing water and wastewater systems?**
Threat actors have been targeting programmable logic controllers (PLCs), altering passwords and disconnecting systems, which can result in boil water notices and manual operations. Investigations are ongoing to determine if these attacks are state-sponsored.
**What does the new open-source AI guidance entail?**
The guidance urges federal agencies to obtain full transparency into AI system components, including training data, before considering a system as open source. This ensures agencies can analyze and remediate potential vulnerabilities.
**What are SBOMs and why are they important?**
Software Bill of Materials are inventories of software components used in systems. Updated every five years, the new SBOM guidelines enhance risk management and supply chain transparency across all software types, including open-source and AI.
**What is SCuBA and how does it help agencies?**
SCuBA, or Secure Cloud Business Applications, is a program aimed at ensuring agencies use standard security configurations for cloud tools. Its recent updates include new baselines for Google Workspace and an improved assessment tool to prevent misconfigurations.
—
### Conclusion
CISA’s latest wave of guidance underscores the growing complexity of cybersecurity in critical sectors. By addressing vulnerabilities in water systems, promoting transparency in open-source AI, and enhancing software and cloud security practices, the agency is proactively strengthening national cyber resilience. These measures are vital as federal agencies and critical infrastructure operators navigate an increasingly sophisticated threat landscape.



